The Administrator wishes to update IPS protections from SmartConsole by clicking on the option `Update Now` under the Updates tab in Threat Tools. Which device requires internet access for the update to work?
A.
Security Gateway only
B.
Only the device where SmartConsole is installed
C.
Only the Security Management Server
D.
Either the Security Management Server or device where SmartConsole is installed
The correct answer is C.
The question is asking about "update now" option under the IPS tab and SMS needs to have internet access in this case.
Yes, you can select "download with SmartConsole" option from the dropdown menu, but the question is asking about "update now"
https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ThreatPrevention_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_ThreatPrevention_AdminGuide/136774
Really people dont read. In your doc clearly states, only SmartConsole internet is needed (Download with SmartConsole):
To update IPS Protections:
In SmartConsole, click Security Policies > Threat Prevention.
In the Threat Tools section, click Updates.
In the IPS section > Update Now, from the drop-down menu, select:
Download with SmartConsole - If your Security Management Server has no internet access.
Download with Security Management Server
Offline Update - If you want to manually upload the file. Select the required file for the update and click Open.
Install Policy.
To update IPS Protections:
In SmartConsole, click Security Policies > Threat Prevention.
In the Threat Tools section, click Updates.
In the IPS section > Update Now, from the drop-down menu, select:
Download with SmartConsole - If your Security Management Server has no internet access.
Download with Security Management Server
Offline Update - If you want to manually upload the file. Select the required file for the update and click Open.
In this case best fit option "D"
You don't have to click to the dropdown menu, you can just click "Update now" and "Download using Security Management server" is preselected as a default option.
The question doesn't mention the dropdown menu, just update now button.
C. Only the Security Management Server
The Security Management Server is responsible for managing and updating security policies, including IPS protections. The Security Gateway (option A) enforces these policies but does not directly fetch updates from the internet. SmartConsole (option B) is the management interface, and while it is used to configure policies, the actual update process is initiated by the Security Management Server. Therefore, internet access is needed for the Security Management Server to fetch the latest IPS.
To update IPS Protections:
In SmartConsole, click Security Policies > Threat Prevention.
In the Threat Tools section, click Updates.
In the IPS section > Update Now, from the drop-down menu, select:
Download with SmartConsole - If your Security Management Server has no internet access.
Download with Security Management Server
Offline Update - If you want to manually upload the file. Select the required file for the update and click Open.
Install Policy.
They state you are updating from Smart Console. Therefore, you only need Internet on the device with Smart Console.
In SmartConsole, click Security Policies > Threat Prevention.
In the Threat Tools section, click Updates.
In the IPS section > Update Now, from the drop-down menu, select:
Download with SmartConsole - If your Security Management Server has no internet access.
Download with Security Management Server
Offline Update - If you want to manually upload the file. Select the required file for the update and click Open.
Install Policy.
You're contradicting yourself. First, you say "you only need Internet on the device with Smart Console." but in your steps you clarify that " select:
Download with SmartConsole - If your Security Management Server has no internet access.". The last part of that statement is key, meaning that you only need internet access from SmartConsole PC, if the SMS does not have internet connectivity
He is not, read it again. You can do it without having internet on your SMS, so optional. On the other hand, having internet in SmartConsole is necessary.
After I've used "Update now" option this message popped up: "Failed to get latest package metadata from user center. Please validate SmartConsole connectivity"
B is correct : when you click on "update now" it take the first option
This was confirmed by tcpdump (10.1.1.10 is my private IP where smartconsole is installed)
23:18:34.339729 IP 10.1.1.10.53931 > 23.57.81.71.https: R 1366:1366(0) ack 10113 win 0
23:18:34.339745 IP 10.1.1.10.53931 > 23.57.81.71.https: R 1366:1366(0) ack 10113 win 0
correct is C CCSA R80 guide
Updates require Internet Connectivity and name resolution from the Security Management Server
upvoted 4 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
C4rlos
Highly Voted 4 years, 7 months agoCCSAChallenger
1 year, 12 months agomucha
Highly Voted 4 years, 6 months agoC4rlos
4 years, 6 months agoRPM99
Most Recent 9 months, 2 weeks agoCCSAChallenger
1 year, 12 months agoHernan_Mella
2 years, 5 months agoDirkd0344
2 years, 9 months agoBezos
2 years, 6 months agoCCSAChallenger
1 year, 12 months agosevasokol44
3 years, 3 months agonayamars
3 years, 5 months agolucacin
3 years, 6 months agoAychi
3 years, 12 months agobabajana
3 years, 12 months ago